Endpoints
CYBEREYE Agent fleet — detections, EDR, coverage
Your endpoint/EDR fleet and agent install. Connect a Wazuh/EDR source for live endpoint alerts.
Endpoints
6
Online
4
Offline / stale
2
Open detections
6
Add an endpoint
Pick the operating system, then run the one-line install on the machine you want to protect — the CYBEREYE Agent enrolls automatically into your workspace.
Windows
powershell -ExecutionPolicy Bypass -Command "iwr -useb https://app.siemsoc.ai/agent/cybereye-agent-windows.ps1 | iex; Install-CybereyeAgent -Token '<your enrollment token>'"The enrollment token is unique to your workspace and already baked into the command above — just copy and run it. Also available for Solaris, AIX and HP-UX on request.
Fleet
| Hostname | OS | Primary user | Version | Status | Last seen |
|---|---|---|---|---|---|
| CODY-MBP-16 | macOS | cody.rhodes@wwe.com | 0.4.2 | Online | 2m ago |
| TRIPLEH-MBP-14 | macOS | triple.h@wwe.com | 0.4.2 | Online | 4m ago |
| KOWENS-WIN-DT | Windows | kevin.owens@wwe.com | 0.4.2 | Online | 1m ago |
| MKTG-WIN-07 | Windows | marketing.ops@wwe.com | 0.4.1 | Online | 7m ago |
| PPV-EDIT-LNX-02 | Linux | creative@wwe.com | 0.4.2 | Offline | 1h ago |
| ROMAN-MBP-14 | macOS | roman.reigns@wwe.com | 0.3.9 | Offline | 2d ago |
Recent endpoint detections
from CYBEREYE AgentCRITICALPossible credential dumping (LSASS access) detected
KOWENS-WIN-DT · 12m ago
HIGHSuspicious PowerShell with encoded command
MKTG-WIN-07 · 48m ago
HIGHUnsigned binary executed from Downloads folder
CODY-MBP-16 · 1h ago
MEDIUMNew launch agent persistence created
TRIPLEH-MBP-14 · 3h ago
MEDIUMOutbound connection to known scanner IP
PPV-EDIT-LNX-02 · 6h ago
LOWmacOS firewall disabled by user
ROMAN-MBP-14 · 12h ago